data:image/s3,"s3://crabby-images/7999f/7999fd34739e952d2cc1009b8f56fdd2ad3cedaa" alt=""
Sometimes, you can encounter an error shown at the bottom right when you try to create a detector or click on security analytics or any other links within the analytics.
For example, in the screenshot below:
data:image/s3,"s3://crabby-images/8b0c5/8b0c528cc0e9d32ca24246822e4bf9a89718dd10" alt=""
data:image/s3,"s3://crabby-images/cd110/cd11036416f1ad9a5db8d55141652ab36e008cf8" alt=""
To fix that:
Option 1:
- Go to Index Management > Indexes
- Search for the index .opensearch-sap-log-types-config
- Delete it.
An example is in the screenshot below:
data:image/s3,"s3://crabby-images/0c7f1/0c7f198097c68fb1f76912cde769fce5afaf7d69" alt=""
- Go to Security Analytics > Threat detectors > Log types
Now you can see lists of Log types.
data:image/s3,"s3://crabby-images/2f9f4/2f9f439e99a98599035e1d9085dbe3f3fb0a251c" alt=""
If you don’t find index .opensearch-sap-log-types-config
Option 2:
- Go to Dev Tools
- Use this command:
GET .opensearch-sap-log-types-config
You will see:
data:image/s3,"s3://crabby-images/ada4e/ada4ef4ad7605cb24611ac7c94e029ee5f58a053" alt=""
- Use this command
DELETE .opensearch-sap-log-types-config
Now, everything works fine, and you can Create a New Detector.
The post OpenSearch: How to Fix Security Analytics Error When You Try to Create a New Detector appeared first on SOC Prime.